CVE-2025-29366

NameCVE-2025-29366
DescriptionIn mupen64plus v2.6.0 there is an array overflow vulnerability in the write_rdram_regs and write_rdram_regs functions, which enables executing arbitrary commands on the host machine.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mupen64plus-core (PTS)bullseye2.5-7vulnerable
bookworm2.5.9+341+gf82b37bf-1vulnerable
forky, sid, trixie2.6.0-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mupen64plus-coresource(unstable)(unfixed)unimportant

Notes

https://github.com/Giles-one/mupen64plusEscape/tree/main/BUG1
https://github.com/mupen64plus/mupen64plus-core/pull/1080
https://github.com/mupen64plus/mupen64plus-core/pull/1119
https://github.com/mupen64plus/mupen64plus-core/pull/1122
https://github.com/mupen64plus/mupen64plus-core/pull/1123
Negligible security impact

Search for package or bug name: Reporting problems